๐ณ๐ฑ
mawan
2023-11-28 01:56:13
(2 years ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack
๐ฉ๐ช
www.elinox.de
2023-11-27 11:51:21
(2 years ago)
27.11.2023 12:51:24 - Wordpress fail
Detected by ELinOX-ALM
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-26 06:48:00
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 26 01:47:54.806264 2023] [security2:error] [pid 13116] [client 146.59.227.252:48534] [client 146.59.227.252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrpinman.org"] [uri "/.git/config"] [unique_id "ZWLqGhi5sK_tucR1e9F6LQAAAAQ"], referer: https://mrpinman.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2023-11-26 05:32:20
(2 years ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-25 21:13:29
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 25 16:13:22.193385 2023] [security2:error] [pid 2926:tid 47513031714560] [client 146.59.227.252:39488] [client 146.59.227.252] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sparkhypnotherapy.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sparkhypnotherapy.com"] [uri "/backup.sql"] [unique_id "ZWJjcvu0k-y3sDBfob6-EwAAAFY"], referer: /
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2023-11-25 10:32:10
(2 years ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2023-11-23 23:02:40
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 23 18:02:34.278108 2023] [security2:error] [pid 11577] [client 146.59.227.252:55070] [client 146.59.227.252] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nifeconsult.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nifeconsult.com"] [uri "/backup.sql"] [unique_id "ZV_aCmsEMkfmzBvnZQcBhQAAABY"], referer: /
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2023-11-22 22:10:45
(2 years ago)
21 attempts against mh_ha-misbehave-ban on rose
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-22 08:02:59
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 22 03:02:53.350295 2023] [security2:error] [pid 17908] [client 146.59.227.252:49648] [client 146.59.227.252] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||biblioteca.atreyu.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "biblioteca.atreyu.net"] [uri "/backup.sql"] [unique_id "ZV21rTfAgGkJBRg0g-EOKwAAAAU"], referer: /
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-22 00:03:36
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 21 19:03:29.544723 2023] [security2:error] [pid 2891] [client 146.59.227.252:59358] [client 146.59.227.252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web215.dnchosting.com"] [uri "/.git/config"] [unique_id "ZV1FUSyeZyB_BcjtGd2fWAAAAAA"], referer: https://web215.dnchosting.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-21 19:17:43
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 21 14:17:37.856998 2023] [security2:error] [pid 12309] [client 146.59.227.252:32966] [client 146.59.227.252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindtoken.app"] [uri "/.git/config"] [unique_id "ZV0CUVdwaXCMuy6J1xf2BgAAAAU"], referer: https://mindtoken.app
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
rakkor
2023-11-21 14:20:23
(2 years ago)
2023/11/21 14:20:22 [error] 21716#21716: *161960 open() "/var/services/web/debug/default/view" faile ...
show more
2023/11/21 14:20:22 [error] 21716#21716: *161960 open() "/var/services/web/debug/default/view" failed (2: No such file or directory), client: 146.59.227.252, server: , request: "GET /debug/default/view?panel=request HTTP/1.1", host: "jksimmons.uk", referrer: "/debug/default/view?panel=request"
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-21 08:01:32
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 21 03:01:26.795588 2023] [security2:error] [pid 10260] [client 146.59.227.252:34464] [client 146.59.227.252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mehtamechanicalinc.com"] [uri "/.git/config"] [unique_id "ZVxj1rN_WsH15_CWqPcXUQAAABA"], referer: https://mehtamechanicalinc.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-11-21 07:46:52
(2 years ago)
(mod_security) mod_security triggered on hostname [redacted] 146.59.227.252 (FR/France/vps-7362f796. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 146.59.227.252 (FR/France/vps-7362f796.vps.ovh.net)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2023-11-21 06:51:51
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 146.59.227.252 (vps-7362f796.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 21 01:51:45.566921 2023] [security2:error] [pid 4291] [client 146.59.227.252:60002] [client 146.59.227.252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "electronstructure.net"] [uri "/.git/config"] [unique_id "ZVxTgfsiYKSfgxsMA63X4QAAAAU"], referer: https://electronstructure.net
show less
Brute-Force
Bad Web Bot
Web App Attack